File tree Expand file tree Collapse file tree
advisories/unreviewed/2026/07 Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-34j8-7jg6-mxhf" ,
4+ "modified" : " 2026-07-24T03:31:55Z" ,
5+ "published" : " 2026-07-24T03:31:55Z" ,
6+ "aliases" : [
7+ " CVE-2026-56160"
8+ ],
9+ "details" : " Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-56160"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56160"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-285"
30+ ],
31+ "severity" : " CRITICAL" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:17:34Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-674h-75hr-643h" ,
4+ "modified" : " 2026-07-24T03:31:55Z" ,
5+ "published" : " 2026-07-24T03:31:55Z" ,
6+ "aliases" : [
7+ " CVE-2026-56167"
8+ ],
9+ "details" : " Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-56167"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56167"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-918"
30+ ],
31+ "severity" : " HIGH" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:17:34Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-8g4r-wj58-m98x" ,
4+ "modified" : " 2026-07-24T03:31:55Z" ,
5+ "published" : " 2026-07-24T03:31:55Z" ,
6+ "aliases" : [
7+ " CVE-2026-62825"
8+ ],
9+ "details" : " Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-62825"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62825"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-287"
30+ ],
31+ "severity" : " CRITICAL" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:17:47Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-c92r-v9xf-6rqc" ,
4+ "modified" : " 2026-07-24T03:31:54Z" ,
5+ "published" : " 2026-07-24T03:31:54Z" ,
6+ "aliases" : [
7+ " CVE-2026-35425"
8+ ],
9+ "details" : " Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-35425"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35425"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-284"
30+ ],
31+ "severity" : " HIGH" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:16:36Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-cfm3-7vpc-px47" ,
4+ "modified" : " 2026-07-24T03:31:55Z" ,
5+ "published" : " 2026-07-24T03:31:55Z" ,
6+ "aliases" : [
7+ " CVE-2026-50517"
8+ ],
9+ "details" : " Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-50517"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50517"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-502"
30+ ],
31+ "severity" : " CRITICAL" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:17:02Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-mrf6-vvvg-7w6c" ,
4+ "modified" : " 2026-07-24T03:31:55Z" ,
5+ "published" : " 2026-07-24T03:31:55Z" ,
6+ "aliases" : [
7+ " CVE-2026-58275"
8+ ],
9+ "details" : " Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-58275"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58275"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-862"
30+ ],
31+ "severity" : " CRITICAL" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:17:40Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-p4xg-f7pp-3rcc" ,
4+ "modified" : " 2026-07-24T03:31:55Z" ,
5+ "published" : " 2026-07-24T03:31:55Z" ,
6+ "aliases" : [
7+ " CVE-2026-54120"
8+ ],
9+ "details" : " Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-54120"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54120"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-20"
30+ ],
31+ "severity" : " CRITICAL" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:17:25Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-w3q8-77x7-hxrq" ,
4+ "modified" : " 2026-07-24T03:31:54Z" ,
5+ "published" : " 2026-07-24T03:31:54Z" ,
6+ "aliases" : [
7+ " CVE-2026-49159"
8+ ],
9+ "details" : " Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-49159"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49159"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-200"
30+ ],
31+ "severity" : " MODERATE" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:16:40Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-w7fc-p5p7-c9pf" ,
4+ "modified" : " 2026-07-24T03:31:55Z" ,
5+ "published" : " 2026-07-24T03:31:55Z" ,
6+ "aliases" : [
7+ " CVE-2026-56165"
8+ ],
9+ "details" : " Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-56165"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56165"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-122"
30+ ],
31+ "severity" : " CRITICAL" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:17:34Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-w7qh-jvr9-qmx9" ,
4+ "modified" : " 2026-07-24T03:31:55Z" ,
5+ "published" : " 2026-07-24T03:31:55Z" ,
6+ "aliases" : [
7+ " CVE-2026-56191"
8+ ],
9+ "details" : " Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V3" ,
13+ "score" : " CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-56191"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56191"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-287"
30+ ],
31+ "severity" : " CRITICAL" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2026-07-24T01:17:36Z"
35+ }
36+ }
You can’t perform that action at this time.
0 commit comments